Description
The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.
Remediation
References
https://github.com/totaljs/framework/commit/c812bbcab8981797d3a1b9993fc42dad3d246f04
https://snyk.io/vuln/SNYK-JS-TOTALJS-1077069
Related Vulnerabilities
CVE-2021-32623 Vulnerability in maven package org.opencastproject:opencast-kernel
CVE-2022-25839 Vulnerability in npm package url-js
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-record-serialization-services
CVE-2022-39322 Vulnerability in npm package @keystone-6/core
CVE-2011-5062 Vulnerability in maven package org.apache.tomcat:catalina